Privacy for Oktapod Android
Effective 26 September 2026 · Package: com.oktapod
Oktapod Android is a client for an agent you choose. It does not create an Oktapod user account or host your agent. The app is developed by Edi Hasaj. For privacy questions, contact edi@oktapod.ai.
How to delete Android app data and request deletion
Your chosen agent
The app sends your access token to your chosen agent for authentication. Messages and the photos, videos, files, and audio clips you choose go to that agent when you press Send. Camera in the + menu opens your phone's camera app; the app receives only the photo you keep, stored in a private cache file that the next photo replaces, and it does not request the camera permission. The app keeps selected files in memory until then. It does not request access to your whole photo library or file store. The Play release requires HTTPS and uses Android's certificate validation.
On a private Tailscale deployment with identity authentication enabled, the app can sign in through your verified Tailscale identity instead of asking you to copy an access key. The signed session stays in app memory and expires. Other deployments require an access key; a private network address alone does not grant access.
Your agent may use model providers, tools, or connected services to carry out a request. Its operator controls those connections, the server's storage and retention, and access to conversation data. Review that operator's policies before connecting. The Android app developer does not receive your conversations automatically.
Data on the phone
The app stores the selected agent address, credentials, conversation identifier, pending sends, and optional phone-pairing credentials in encrypted device storage protected by Android Keystore. Android backup is disabled for the app. Conversation history is retrieved from your agent.
Disconnect pauses automatic reconnection. Forget this agent removes saved connection data, pending sends, and phone access from this device. It does not delete conversations or revoke credentials on the server. Contact the agent operator or use its data controls for server-side deletion and revocation.
System notifications
If you allow notifications, the app gets a device registration token from Google Firebase Cloud Messaging and sends it to your chosen agent. The agent uses that token to request Android system notifications for explicit agent events and completed work. Notification text is generic. It does not include messages or agent replies. Google handles delivery under its own privacy terms.
If your agent does not hold its own notification keys, it asks the Oktapod push service at push.oktapod.ai to deliver the alert. The service receives only the device token and whether the alert is an update or a reaction; it chooses the generic text itself, never receives messages or replies, and does not store the token. It keeps only short-lived rate-limit counters derived from a one-way hash of the token.
You can turn notifications off in Android settings. Disconnect and Forget this agent ask the connected agent to remove its token when it is reachable. If it is offline, ask its operator to remove the token from that server.
Network discovery and phone pairing
Local discovery sends standard service-discovery queries on the connected network and checks candidate agent endpoints. Those checks contain no access token or chat content. Discovery is a suggestion, not authorization to use a server.
If you enable phone pairing, the app exchanges a generated node identifier and scoped credentials with your agent. In this version, the agent can request opening an HTTPS sign-in page. You decide before the system browser opens. Phone requests are processed while the app is open.
The app does not request camera, contacts, SMS, precise location, notification-listener, or accessibility-service permissions.
Dictation
When you tap the microphone in the message box, the app asks Android's speech recognizer to turn what you say into text in that box, and prefers offline recognition. Nothing is sent to your agent until you press Send. On many phones the recognizer is Google's speech service, which may process the audio under Google's privacy policy when offline recognition is not available. The app does not record, store, or send the audio itself, and it uses the microphone only while you dictate. Android asks for microphone permission the first time, and you can turn it off in the system settings.
Optional crash reports
Crash reporting is off by default. If enabled, it sends the app release and a bounded error-type label to the developer's private error service at errors.applifyer.com. Conversation text, access tokens, agent addresses, requests, stack traces, and breadcrumbs are excluded. You can turn reporting off in Privacy and diagnostics.
Reports you submit
You can report an app issue from the menu or long-press an assistant message to report that reply. The form sends your selected report category and comment to the developer. Including the selected reply is optional and requires an explicit checkbox. The rest of your conversation, your agent address, and connection credentials are not included.
Reports are used for support, security, and content-safety improvements. The developer's active report store retains reports for up to 30 days; rotating backups can retain a removed report for up to seven further days. Keep the report receipt if you want to request deletion by email.
Optional installation counts
Builds with an installation-count service offer an off-by-default “Count this installation” switch. If you enable it, the app sends a random installation ID, app version, platform, and UTC active day to the developer's count service at most once a day. This is separate from crash reporting. The service stores a hash of that random ID, first and last active day, version, and platform. It does not store conversations, agent addresses, accounts, hardware identifiers, or IP addresses.
Turning the switch off stops check-ins and requests deletion. If offline, deletion retries on the next active day. Inactive records are pruned after 90 days. Counts describe participating installations, not unique people. An unconfigured build sends no installation counts and does not show the switch.
Advertising and payments
The Android app contains no advertising, advertising identifiers, or payment collection. A model provider or agent operator you choose may have its own charges and data practices.
Changes and contact
This page will be updated when the app's data handling changes. For questions or requests about developer-held reports, email edi@oktapod.ai. For data held by your chosen agent or its providers, contact that operator.